Release date 2026/09/15
Bugfix
Fixed an unreachable code path that prevented the plugin from falling back to validating the
samlp:Response-level signature when thesaml:Assertionwas not individually signed. Withvalidate_assertion_signatureenabled, an unsigned assertion inside a signed Response is now accepted (and a Response with no valid signature on either the assertion or the root is rejected), so IdPs that sign the Response envelope rather than the assertion no longer require signature validation to be turned off. Relates to the Response-level fallback described in CVE-2026-14917.Fixed CVE-2026-14917 by validating the
samlp:Responsesignature whenever anidp_certificateis configured – even whenvalidate_assertion_signatureis disabled – and logging a warning when neither is set, preventing an unauthenticated attacker from impersonating any user with a crafted unsigned SAML response, under configurations that setvalidate_assertion_signaturetofalse.Hardened signature validation against XML Signature Wrapping. The plugin now checks that the signature
Reference URIis a same-document fragment that names theIDof the element it digests and consumes, so a signature can no longer be bound to a different element than the one that provides the identity. A response whose reference URI is empty or not a same-document fragment is now rejected.